Skip to main content

Scopes Reference

Scope Hierarchy & Inheritance

  • Permissions are organized in a hierarchical tree. Granting a parent scope (e.g. delegated:profile:all) automatically authorizes all child scopes (such as delegated:profile:read, delegated:profile:write, delegated:profile:2fa:all).
  • Wildcards (*, admin:all, delegated:all, client:all) authorize all sub-permissions under their respective namespace.
  • You can switch between Tree View and Table View below, and search across names, namespaces, and descriptions.

Showing 98 of 98 total scopes
*Wildcard

View and manage everything in the system.

delegated:allWildcardparent: *

View and manage your account.

Delegated Admin:View and manage a user's account on behalf of them using delegated access.
delegated:system:settings:readparent: delegated:all

View system settings.

Delegated Admin:View system settings on behalf of a user.
delegated:roles:allWildcardparent: delegated:all

View and manage your roles.

Delegated Admin:View and manage user roles on behalf of a user.
delegated:profile:allWildcardparent: delegated:all

View and manage your profile information.

Delegated Admin:View and manage user profile information on behalf of a user.
delegated:social:allWildcardparent: delegated:all

View and manage information about people you follow and people you've blocked.

Delegated Admin:View and manage social features like following and blocking on behalf of a user.
client:allWildcardparent: *

View and manage accounts in the system using headless application access.

client:roles:allWildcardparent: client:all

View and manage roles in the system.

client:system:allWildcardparent: client:all

View and manage the system.

client:oauth:allWildcardparent: client:all

View and manage OAuth information.

client:social:allWildcardparent: client:all

View and manage social features in the system.

client:profile:allWildcardparent: client:all

View and manage profile information of user accounts in the system.

client:configuration:readparent: client:all

Read system configurations.

client:profile:sensitive:allWildcardparent: client:all

Read and write to all levels sensitive fields of users.

admin:allWildcardparent: *

View and manage user accounts in the system using admin APIs.

admin:roles:allWildcardparent: admin:all

View and manage roles in the system.

admin:system:allWildcardparent: admin:all

View and manage the system.

admin:profile:allWildcardparent: admin:all

View and manage profile information of user accounts in the system.

admin:social:allWildcardparent: admin:all

View and manage social features in the system.

admin:configuration:readparent: admin:all

Read system configurations.

admin:profile:sensitive:allWildcardparent: admin:all

Read and write to all levels sensitive fields of users.